Company Brain

Resources

Data handling and security

Company Brain is an early product for operational source material from one team or function. Ordinary confidential operational files are allowed within that boundary.

You should know what can be uploaded today and what remains out of scope.

What can be uploaded today

Use ordinary operational files from one team or function, including support macros, SOPs, customer-success notes, ticket exports, internal workflows, and call transcripts. Redacted or sanitized examples are still fine, but users do not need to manually sanitize normal business documents first.

What stays narrow

The trial is for source material from one support, onboarding, RevOps, customer-success, or operations-heavy team. Do not upload broad archives, whole-company exports, or material unrelated to that team or function boundary.

What remains out of scope

Do not upload secrets, credentials, payment data, regulated health, legal, or financial data, highly confidential strategy, private employee records, special-compliance material, or anything your organization cannot share under its own obligations.

What the hosted trial stores

  • Application records, account records, and session records.
  • For uploads, source filenames and parse metadata, run hashes and summaries, and up to 500 characters of preview per pasted or file source. The original file bytes are not stored by the current upload flow, and full extracted source text is not kept as a separate retained field after processing.
  • Generated output packs, evidence quotes and source snippets, review edits, approval metadata, and final exports can retain source-derived content.
  • Post-export debrief answers and internal trial accounting records.

Hosting and service providers

  • Production runs on a Hetzner VPS in Hillsboro, Oregon, with PostgreSQL in the same hosted environment and verified backup and restore procedures.
  • OpenAI processes readable source text to generate the draft pack. Company Brain disables response application-state storage for these requests. OpenAI's API data controls describe its provider-level training and retention defaults; Company Brain does not claim Zero Data Retention.
  • Stytch handles work-email verification, secure return links, and managed sessions. Proton SMTP handles operational email. Polar handles optional hosted credit-top-up checkout and does not receive uploaded source material through that checkout flow.
  • When public-acquisition analytics is enabled, PostHog receives only manual, personless events from unauthenticated public pages: page family, article slug, /try or /apply destination, normalized referring host, allowlisted campaign labels, and a coarse trial-submission result. Company Brain does not send names, email addresses, form values, source material, prompts, previews, outputs, account or run identifiers, full URLs, query strings, or raw referrers. PostHog does not load on login, workspace, admin, checkout, review, export, or other customer-data surfaces.

Access and transport controls

  • Traffic uses HTTPS. Workspace passwords are salted and scrypt-hashed, and Company Brain session tokens are stored as hashes.
  • Workspace content requires an authenticated session. Existing users return by secure email link or by a workspace password they set.
  • Server-side customer-data access is scoped to the authenticated organization. Public uploads also have size and rate limits.
  • A named trusted operator may access customer data only for a specific support, incident, recovery, export or deletion, deployment, or verified-bug reason. Operators start with metadata and inspect content only when necessary, then record a sanitized private note. This is limited operational auditability, not enterprise RBAC or audit logging.

Retention, export, and deletion

  • Company Brain does not yet provide self-service retention settings or a published automatic deletion schedule. Trial records remain while the workspace is active.
  • Support can provide one organization's scoped trial-data export, including reviewed or finalizable output-pack data, related source metadata, debrief answers, and trial-accounting records.
  • On request, an operator can tombstone the active datastore: sessions are removed; identities, source previews, generated packs, review edits, exports, and debrief answers are removed or anonymized; minimal run and trial-usage audit records remain.
  • Recovery backups may contain earlier copies and are managed operationally. Deletion of the active datastore is not an immediate deletion guarantee for every backup. Contact Company Brain support to request export or deletion.
  • The current trial does not provide legal hold, automated redaction, DLP scanning, SSO, RBAC, customer-managed keys, or a general encryption-at-rest guarantee.

Practical rule

Upload only what is needed to understand one team or operating area. Ordinary confidential operational files are OK; restricted material stays out.

Read next